# Elastic agent transfer via logstahsh with incomplete logs

**URL:** <https://discuss.elastic.co/t/elastic-agent-transfer-via-logstahsh-with-incomplete-logs/326482>\
**Category:** Elastic Agent\
**Created:** [February 25, 2023, 1:59am UTC](https://discuss.elastic.co/t/elastic-agent-transfer-via-logstahsh-with-incomplete-logs/326482 "2023-02-25T01:59:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![xqaiviwjxzw](https://avatars.discourse-cdn.com/v4/letter/x/bbce88/32.png) [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Post date:** [February 25, 2023, 1:59am UTC](https://discuss.elastic.co/t/elastic-agent-transfer-via-logstahsh-with-incomplete-logs/326482/1 "2023-02-25T01:59:31Z")

</div>

1.elastic agent transfer via logstahsh, endpoint shows healthy but logs are not coming in, what is the reason? Is there any solution for this?

The endpoint is viewed locally with the following result?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/4/3403a23ee301cd3e65f5774d5d399743508a92b5.jpeg)

2.elastic agent shows unhealthy error report

```auto
failed to dispatch actions, error: operator: failed to execute step sc-run, error: failed to start connection credentials listener: listen tcp 127.0.0.1:6788: bind: Only one usage of each socket address (protocol/network address/port) is normally permitted.: failed to start connection credentials listener: listen tcp 127.0.0.1:6788: bind: Only one usage of each socket address (protocol/network address/port) is normally permitted.

```

---

<div class="post-metadata">

**Author:** ![gabriel.landau](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel.landau/32/73401_2.png) [@gabriel.landau](https://discuss.elastic.co/u/gabriel.landau)\
**Post date:** [February 27, 2023, 3:47pm UTC](https://discuss.elastic.co/t/elastic-agent-transfer-via-logstahsh-with-incomplete-logs/326482/2 "2023-02-27T15:47:35Z")

</div>

This appears to be an [Agent issue](https://github.com/elastic/elastic-agent/blob/e7419ddc4e492e7e41acd20ec39f570937affe13/pkg/component/runtime/conn_info_server.go#L30-L33). Transferring to Elastic Agent.

---

<div class="post-metadata">

**Author:** ![xqaiviwjxzw](https://avatars.discourse-cdn.com/v4/letter/x/bbce88/32.png) [@xqaiviwjxzw](https://discuss.elastic.co/u/xqaiviwjxzw)\
**Post date:** [February 28, 2023, 4:01am UTC](https://discuss.elastic.co/t/elastic-agent-transfer-via-logstahsh-with-incomplete-logs/326482/3 "2023-02-28T04:01:10Z")

</div>

hello, what can be done about this?

---

<div class="post-metadata">

**Author:** ![gabriel.landau](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gabriel.landau/32/73401_2.png) [@gabriel.landau](https://discuss.elastic.co/u/gabriel.landau)\
**Post date:** [February 28, 2023, 4:08pm UTC](https://discuss.elastic.co/t/elastic-agent-transfer-via-logstahsh-with-incomplete-logs/326482/4 "2023-02-28T16:08:05Z")

</div>

This appears similar to Agent bugs [#761](https://github.com/elastic/elastic-agent/issues/761) and [#2008](https://github.com/elastic/elastic-agent/issues/2008). Can you try the workaround described in #2008 and see if it resolves your issue?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 28, 2023, 4:08pm UTC](https://discuss.elastic.co/t/elastic-agent-transfer-via-logstahsh-with-incomplete-logs/326482/5 "2023-03-28T16:08:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
